CVE-2026-25592: Microsoft Semantic Kernel Command Injection Vulnerability
A vulnerability in Microsoft's Semantic Kernel agent framework where model output reaching a shell can lead to command injection. Patched by Microsoft.
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
A vulnerability in Microsoft's Semantic Kernel agent framework where model output reaching a shell can lead to command injection. Patched by Microsoft.
Microsoft researchers have disclosed a novel exploit chain named AutoJack that allows a single malicious web page to hijack an AI browsing…
Another command injection vulnerability in Microsoft Semantic Kernel related to insecure shell command handling.
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's…
Threat actors are actively exploiting a recently patched medium-severity information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on…
CVE-2013-3307 is a vulnerability in certain Linksys router models that allows remote attackers to execute arbitrary code. This flaw, dating from 2013,…
CVE-2016-5681 is a vulnerability in D-Link router models that allows remote attackers to execute arbitrary code. This flaw is exploited by the…
CVE-2025-11837 is a code injection vulnerability in QNAP's Malware Remover application, demonstrated at Pwn2Own Ireland 2025. Patched in November 2025, it is…
CVE-2026-43512 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-42579 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…